# Latest

**URL:** https://discuss.elastic.co/latest.md?page=389

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 390

---

## [Search Query DSL for App Search](https://discuss.elastic.co/t/search-query-dsl-for-app-search/354076)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 1\
**Last updated:** [February 26, 2024, 3:53pm UTC](https://discuss.elastic.co/t/search-query-dsl-for-app-search/354076 "2024-02-26T15:53:14Z")

</div>

Hi I want to ask, how to access App Search using Dev tool? Can it be translated into query DSL? I want to test the relevance tuning results from the Dev Tool before apply it to our application

---

## [Possible to Create kibana indexes from application code?](https://discuss.elastic.co/t/possible-to-create-kibana-indexes-from-application-code/353432)

<div class="topic-metadata">

**Author:** [@navya\_k](https://discuss.elastic.co/u/navya_k)\
**Replies:** 3\
**Last updated:** [February 26, 2024, 3:42pm UTC](https://discuss.elastic.co/t/possible-to-create-kibana-indexes-from-application-code/353432 "2024-02-26T15:42:43Z")

</div>

Hello, I would like to ask question like. There was a Java application which deployed to elastic kibana. Now there is a need to create indexes for it, we can go ahead and write up in kibana - index management. But my q…

---

## [Kibana cannot visualize my variables. ](https://discuss.elastic.co/t/kibana-cannot-visualize-my-variables/354069)

<div class="topic-metadata">

**Author:** [@Clinton\_Pillay](https://discuss.elastic.co/u/Clinton_Pillay)\
**Replies:** 1\
**Last updated:** [February 26, 2024, 3:37pm UTC](https://discuss.elastic.co/t/kibana-cannot-visualize-my-variables/354069 "2024-02-26T15:37:48Z")

</div>

So im completely new to Kibana, and having challanges creating visualzations. I have my data imported sucessfully into Elasticsearch. I have 2 values(date(ISO8601 date and value(number type)). So I want to visualize a …

---

## [Question regarding filebeat indexes for version 8.11.x and ILM](https://discuss.elastic.co/t/question-regarding-filebeat-indexes-for-version-8-11-x-and-ilm/352726)

<div class="topic-metadata">

**Author:** [@Ravi\_Pattar](https://discuss.elastic.co/u/Ravi_Pattar)\
**Replies:** 9\
**Last updated:** [February 26, 2024, 3:04pm UTC](https://discuss.elastic.co/t/question-regarding-filebeat-indexes-for-version-8-11-x-and-ilm/352726 "2024-02-26T15:04:49Z")

</div>

Hi @all I am seeing an issue on the ELK production server w.r.t to ILM. We have a production server (standalone) where ELK stack is installed and has the version 7.17.15. Recently ILM policy was implemented and is run…

---

## [Json.keys\_under\_root ignored for JSON documents larger than 4096 bytes](https://discuss.elastic.co/t/json-keys-under-root-ignored-for-json-documents-larger-than-4096-bytes/354127)

<div class="topic-metadata">

**Author:** [@vegard](https://discuss.elastic.co/u/vegard)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 2:46pm UTC](https://discuss.elastic.co/t/json-keys-under-root-ignored-for-json-documents-larger-than-4096-bytes/354127 "2024-02-26T14:46:38Z")

</div>

Hi, we seem to be hitting a hard limit on our Custom Logs integration for the Elastic Agent, ingesting json logs. We have the following custom configuration: json: keys\_under\_root: true This works fine for all json …

---

## [Updating elasticsearch CA but \_ssl/certificates return wrong result](https://discuss.elastic.co/t/updating-elasticsearch-ca-but-ssl-certificates-return-wrong-result/354085)

<div class="topic-metadata">

**Author:** [@petertw6235](https://discuss.elastic.co/u/petertw6235)\
**Replies:** 5\
**Last updated:** [February 26, 2024, 1:08pm UTC](https://discuss.elastic.co/t/updating-elasticsearch-ca-but-ssl-certificates-return-wrong-result/354085 "2024-02-26T13:08:29Z")

</div>

Hi, Elasticsearch version: 7.17.9 I tried to update the TLS certificate because the CA will expire this year. I found this guide \[same CA\] (Update certificates with the same CA | Elasticsearch Guide \[7.17\] | Elastic) …

---

## [Filter the Nth serial numbers with highest count](https://discuss.elastic.co/t/filter-the-nth-serial-numbers-with-highest-count/354002)

<div class="topic-metadata">

**Author:** [@robertomzc](https://discuss.elastic.co/u/robertomzc)\
**Replies:** 2\
**Last updated:** [February 26, 2024, 12:30pm UTC](https://discuss.elastic.co/t/filter-the-nth-serial-numbers-with-highest-count/354002 "2024-02-26T12:30:57Z")

</div>

Hi all! I am trying to do a scatter plot with Vega-Lite that shows the evolution of capacity of some batteries with time. The colors in the plot should correspond to the different batteries (serial number). Find below a…

---

## [Uptime monitors false positive results](https://discuss.elastic.co/t/uptime-monitors-false-positive-results/351976)

<div class="topic-metadata">

**Author:** [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Replies:** 12\
**Last updated:** [February 26, 2024, 12:17pm UTC](https://discuss.elastic.co/t/uptime-monitors-false-positive-results/351976 "2024-02-26T12:17:01Z")

</div>

Hi I've added a monitor and its giving continuous false positive results I want to know why it is checking 2 times at every interval time A first its showing correct and then againg checks and shows FP results

---

## [Elastic stack change from GCP to AWS](https://discuss.elastic.co/t/elastic-stack-change-from-gcp-to-aws/354098)

<div class="topic-metadata">

**Author:** [@Vilius\_Dudenas](https://discuss.elastic.co/u/Vilius_Dudenas)\
**Replies:** 1\
**Last updated:** [February 26, 2024, 11:52am UTC](https://discuss.elastic.co/t/elastic-stack-change-from-gcp-to-aws/354098 "2024-02-26T11:52:09Z")

</div>

Hey, I am currently investigating what would be the best approach to migrate current deployment from GCP to AWS. As I see snapshots are tied to the provider and it does not allow me to restore on another provider (prob…

---

## [Alerts configuration via mail through KIBANA](https://discuss.elastic.co/t/alerts-configuration-via-mail-through-kibana/354118)

<div class="topic-metadata">

**Author:** [@2328943\_dc](https://discuss.elastic.co/u/2328943_dc)\
**Replies:** 1\
**Last updated:** [February 26, 2024, 11:41am UTC](https://discuss.elastic.co/t/alerts-configuration-via-mail-through-kibana/354118 "2024-02-26T11:41:00Z")

</div>

We are using Free Install of KIBANA. Is it possible to create email alert for logs in elasticsearch and how can i configure it in KIBANA UI .

---

## [Snapshot name from original index name as a suffix](https://discuss.elastic.co/t/snapshot-name-from-original-index-name-as-a-suffix/353353)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 3\
**Last updated:** [February 26, 2024, 11:08am UTC](https://discuss.elastic.co/t/snapshot-name-from-original-index-name-as-a-suffix/353353 "2024-02-26T11:08:00Z")

</div>

Hi Is it possible to make configuration for shift the name from original index to snapshot name? I need such config because many of index are generate with name in date order so I want to know which one index has snapsh…

---

## [Elastic Search curator not working](https://discuss.elastic.co/t/elastic-search-curator-not-working/354114)

<div class="topic-metadata">

**Author:** [@Akash\_Rai](https://discuss.elastic.co/u/Akash_Rai)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 10:42am UTC](https://discuss.elastic.co/t/elastic-search-curator-not-working/354114 "2024-02-26T10:42:34Z")

</div>

Hi , I am trying to install elastisearch -curator but its not working. kind: CronJob metadata: name: curator labels: app: curator spec: schedule: "\* \* \* \* \*" successfulJobsHistoryLimit: 1 failedJobsHistoryLimit…

---

## [Datastream under a policy behaving unstable](https://discuss.elastic.co/t/datastream-under-a-policy-behaving-unstable/353144)

<div class="topic-metadata">

**Author:** [@Mubolio](https://discuss.elastic.co/u/Mubolio)\
**Replies:** 1\
**Last updated:** [February 26, 2024, 10:35am UTC](https://discuss.elastic.co/t/datastream-under-a-policy-behaving-unstable/353144 "2024-02-26T10:35:55Z")

</div>

Hello, I have a datastream that should keep data only for the latest 15 days, documents that are older than 15 days will be deleted(based on the @timestamp field). This is the index template attached to the datastream: …

---

## [APM version 1.26.0 - "the selected trace cannot be found "](https://discuss.elastic.co/t/apm-version-1-26-0-the-selected-trace-cannot-be-found/354111)

<div class="topic-metadata">

**Author:** [@Premysl\_Capek](https://discuss.elastic.co/u/Premysl_Capek)\
**Replies:** 1\
**Last updated:** [February 26, 2024, 10:29am UTC](https://discuss.elastic.co/t/apm-version-1-26-0-the-selected-trace-cannot-be-found/354111 "2024-02-26T10:29:22Z")

</div>

If I use Elastic.Apm.NetCoreAll version 1.26.0 I see this message instead of transactions: Works with version 1.25.3 Server version is 8.12.1 for all components.

---

## [Python client multisearch with different fields weights](https://discuss.elastic.co/t/python-client-multisearch-with-different-fields-weights/354064)

<div class="topic-metadata">

**Author:** [@Marco\_Solari](https://discuss.elastic.co/u/Marco_Solari)\
**Replies:** 5\
**Last updated:** [February 26, 2024, 10:13am UTC](https://discuss.elastic.co/t/python-client-multisearch-with-different-fields-weights/354064 "2024-02-26T10:13:05Z")

</div>

I'm quite new to elasticsearch... I created my first index (to be used for italian language), and basic search functionality, for my cooking recipes database. I now am trying to implement some more advanced search feat…

---

## [ECK : can't have green elasticsearch cluster](https://discuss.elastic.co/t/eck-cant-have-green-elasticsearch-cluster/354106)

<div class="topic-metadata">

**Author:** [@Bobflyer](https://discuss.elastic.co/u/Bobflyer)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 9:55am UTC](https://discuss.elastic.co/t/eck-cant-have-green-elasticsearch-cluster/354106 "2024-02-26T09:55:40Z")

</div>

Hello, I try to deploy an elasticsearch cluster on my docker-desktop kubernetes test cluster. The final goal is to deploy it in a k3s cluster on my raspberry pies. Here my kubernetes manifest : apiVersion: elasticsear…

---

## [Elastic Search UI - Adding filter returns all results](https://discuss.elastic.co/t/elastic-search-ui-adding-filter-returns-all-results/354095)

<div class="topic-metadata">

**Author:** [@jackfrost](https://discuss.elastic.co/u/jackfrost)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 8:11am UTC](https://discuss.elastic.co/t/elastic-search-ui-adding-filter-returns-all-results/354095 "2024-02-26T08:11:21Z")

</div>

Hey All. I am use Elasticsearch ui with the @elastic/search-ui-elasticsearch-connector. I currently have the search up and running. I am able to do a search for something like a name, and get one exact result back. All …

---

## [Connect Git to ELK](https://discuss.elastic.co/t/connect-git-to-elk/353954)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 4\
**Last updated:** [February 26, 2024, 7:11am UTC](https://discuss.elastic.co/t/connect-git-to-elk/353954 "2024-02-26T07:11:47Z")

</div>

Hi, im trying to export all the saved object to insert all object inside a repository. Someone know if is possible connect kibana and git in easier way? Thanks in advance

---

## [\[mysql\]queries cannot be logged](https://discuss.elastic.co/t/mysql-queries-cannot-be-logged/354087)

<div class="topic-metadata">

**Author:** [@h32309](https://discuss.elastic.co/u/h32309)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 6:55am UTC](https://discuss.elastic.co/t/mysql-queries-cannot-be-logged/354087 "2024-02-26T06:55:52Z")

</div>

When the query field contains a type of DOUBLE, the query cannot be logged.

---

## [The number of my es's file descriptor keep growing,I need help](https://discuss.elastic.co/t/the-number-of-my-ess-file-descriptor-keep-growing-i-need-help/354080)

<div class="topic-metadata">

**Author:** [@SKYWALKER-STAR](https://discuss.elastic.co/u/SKYWALKER-STAR)\
**Replies:** 1\
**Last updated:** [February 26, 2024, 5:55am UTC](https://discuss.elastic.co/t/the-number-of-my-ess-file-descriptor-keep-growing-i-need-help/354080 "2024-02-26T05:55:50Z")

</div>

The number of my es's file descriptor keep growing.How can i reduce the my file descriptor number used by my es cluster.

---

## [Trying to visulaize the working of a dead letter queue but getting error while creating index](https://discuss.elastic.co/t/trying-to-visulaize-the-working-of-a-dead-letter-queue-but-getting-error-while-creating-index/354078)

<div class="topic-metadata">

**Author:** [@Karan37](https://discuss.elastic.co/u/Karan37)\
**Replies:** 2\
**Last updated:** [February 26, 2024, 5:46am UTC](https://discuss.elastic.co/t/trying-to-visulaize-the-working-of-a-dead-letter-queue-but-getting-error-while-creating-index/354078 "2024-02-26T05:46:23Z")

</div>

This is my logstash configuration input { file{ path =\> "C:\\Elastic Stack\\logstash-8.12.0\\config\\sample-data-dlq.json" start\_position =\> "beginning" sincedb\_path =\> "NUL" codec =\> "json" } } filter{ …

---

## [Elastic Search is getting restarted by few second time period -- Sowing Kibana server is not ready yet](https://discuss.elastic.co/t/elastic-search-is-getting-restarted-by-few-second-time-period-sowing-kibana-server-is-not-ready-yet/353863)

<div class="topic-metadata">

**Author:** [@dinakar](https://discuss.elastic.co/u/dinakar)\
**Replies:** 2\
**Last updated:** [February 26, 2024, 5:07am UTC](https://discuss.elastic.co/t/elastic-search-is-getting-restarted-by-few-second-time-period-sowing-kibana-server-is-not-ready-yet/353863 "2024-02-26T05:07:54Z")

</div>

I tried to resatrt the Kibana and the elasticsearch for renewing the certificate of server, after I'm facing the following error. Appreciate if anyone provide the solution for the same ASAP. \* Kibana logs, Caused by: ki…

---

## [ILM Policy on No alias](https://discuss.elastic.co/t/ilm-policy-on-no-alias/354077)

<div class="topic-metadata">

**Author:** [@Suresh\_Ghatuwa](https://discuss.elastic.co/u/Suresh_Ghatuwa)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 4:11am UTC](https://discuss.elastic.co/t/ilm-policy-on-no-alias/354077 "2024-02-26T04:11:34Z")

</div>

Hello, I am trying to implement the ILM policy on index not having an alias. ILM policy need to be trigger on removing an alias from index immediately. Could you please suggest if that is possible ? Thanks in advance. …

---

## [Dynamic way of building aggregation query using java api client](https://discuss.elastic.co/t/dynamic-way-of-building-aggregation-query-using-java-api-client/353946)

<div class="topic-metadata">

**Author:** [@prasad.ram1431](https://discuss.elastic.co/u/prasad.ram1431)\
**Replies:** 1\
**Last updated:** [February 26, 2024, 3:48am UTC](https://discuss.elastic.co/t/dynamic-way-of-building-aggregation-query-using-java-api-client/353946 "2024-02-26T03:48:23Z")

</div>

Hi Team, Can someone please help with sample code to create aggregate query dynamically based on the given list of fields using Elasticsearch Java API Client. Unfortunately I couldn't get much documentation help on this…

---

## [Issue with Elasticsearch Cluster](https://discuss.elastic.co/t/issue-with-elasticsearch-cluster/354075)

<div class="topic-metadata">

**Author:** [@Jimmy\_Wang](https://discuss.elastic.co/u/Jimmy_Wang)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 3:28am UTC](https://discuss.elastic.co/t/issue-with-elasticsearch-cluster/354075 "2024-02-26T03:28:43Z")

</div>

Hello, I am currently setting up an Elasticsearch cluster with three nodes and encountering an issue with cluster formation. Here's the setup: elastic01: 10G network interface with VLAN configured, able to join the clu…

---

## [Choosing ECK for Openshift Cluster](https://discuss.elastic.co/t/choosing-eck-for-openshift-cluster/354074)

<div class="topic-metadata">

**Author:** [@rhowin](https://discuss.elastic.co/u/rhowin)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 3:25am UTC](https://discuss.elastic.co/t/choosing-eck-for-openshift-cluster/354074 "2024-02-26T03:25:09Z")

</div>

Hello Team, Need your advice to have a better monitoring method unlike we have it for our current OpenShift cluster, which is running on the version 4.12.40. We are looking out for features which also includes the appli…

---

## [Dynamic template copy\_to does not work with flattened type](https://discuss.elastic.co/t/dynamic-template-copy-to-does-not-work-with-flattened-type/354026)

<div class="topic-metadata">

**Author:** [@s.moran](https://discuss.elastic.co/u/s.moran)\
**Replies:** 1\
**Last updated:** [February 25, 2024, 11:36pm UTC](https://discuss.elastic.co/t/dynamic-template-copy-to-does-not-work-with-flattened-type/354026 "2024-02-25T23:36:16Z")

</div>

I have a field of flattened type that contains a subfield that I want to do numeric range searches on. I am trying to use a dynamic template to copy the field's value to a top level field that I can use for range queries…

---

## [Kibana inaccessible](https://discuss.elastic.co/t/kibana-inaccessible/354056)

<div class="topic-metadata">

**Author:** [@eloi-gn](https://discuss.elastic.co/u/eloi-gn)\
**Replies:** 5\
**Last updated:** [February 25, 2024, 9:30pm UTC](https://discuss.elastic.co/t/kibana-inaccessible/354056 "2024-02-25T21:30:42Z")

</div>

Hello, I set up a k3s cluster using ubuntu. I want to install ELK on my cluster. So I installed elasticsearch and Kibana with the Debian package in version 7.6.1. I left the elastic and Kibana configuration as default. f…

---

## [ES|QL CIDR\_MATCH not working (or more likely I'm doing something wrong)?](https://discuss.elastic.co/t/es-ql-cidr-match-not-working-or-more-likely-im-doing-something-wrong/350035)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 1\
**Last updated:** [February 25, 2024, 8:05pm UTC](https://discuss.elastic.co/t/es-ql-cidr-match-not-working-or-more-likely-im-doing-something-wrong/350035 "2024-02-25T20:05:55Z")

</div>

Hi All, I've been messing around with ES|QL a bit, but I'm having an issue with the CIDR\_MATCH function, I'm hoping someone can help with. At a minimum, I have a document that looks like: { "host": { "name": "ip…

---

## [Regarding issues related to the ES SSPL protocol](https://discuss.elastic.co/t/regarding-issues-related-to-the-es-sspl-protocol/354058)

<div class="topic-metadata">

**Author:** [@liruileay](https://discuss.elastic.co/u/liruileay)\
**Replies:** 2\
**Last updated:** [February 25, 2024, 7:47pm UTC](https://discuss.elastic.co/t/regarding-issues-related-to-the-es-sspl-protocol/354058 "2024-02-25T19:47:02Z")

</div>

The customer service within the company based on ES encapsulation belongs to the provision of products as services to the outside world. Do we need commercial authorization or open source code

[Previous page](https://discuss.elastic.co/latest.md?page=388)

[Next page](https://discuss.elastic.co/latest.md?page=390)
